kol-discovery

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a local Python script to orchestrate the discovery and scoring of influencers.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves data from Apify's well-known service and the author's official GooseWorks API.
  • [PROMPT_INJECTION]: The skill is subject to indirect prompt injection because it processes untrusted text from LinkedIn posts. Ingestion points: LinkedIn post content retrieved via Apify API in scripts/kol_discovery.py. Boundary markers: None identified. Capability inventory: Network operations via urllib.request and local CSV file creation. Sanitization: None; raw post content is used for scoring calculations and preview generation in the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 10:48 AM